CVE-2012-5450 – CMS Made Simple 1.11.2 Cross Site Request Forgery
https://notcve.org/view.php?id=CVE-2012-5450
Cross-site request forgery (CSRF) vulnerability in lib/filemanager/imagemanager/images.php in CMS Made Simple (CMSMS) 1.11.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deld parameter. Una vulnerabilidad de falsificación de peticiones en sitios cruzados (CSRF) en lib/filemanager/ImageManager/images.php en CMS Made Simple (CMSMS) v1.11.2 y anteriores permite a atacantes remotos secuestrar la autenticación de los administradores de las peticiones que borran archivos de su elección a través del parámetro 'deld'. CMS Made Simple version 1.11.2 suffers from a cross site request forgery vulnerability. • http://archives.neohapsis.com/archives/bugtraq/2012-11/0035.html http://forum.cmsmadesimple.org/viewtopic.php?f=1&t=63545 http://packetstormsecurity.org/files/117951/CMS-Made-Simple-1.11.2-Cross-Site-Request-Forgery.html http://secunia.com/advisories/51185 http://viewsvn.cmsmadesimple.org/diff.php?repname=cmsmadesimple&path=%2Ftrunk%2Flib%2Ffilemanager%2FImageManager%2FClasses%2FImageManager.php&rev=8400&peg=8498 https://exchange.xforce.ibmcloud.com/vulnerabilities/79881 https://www.htbridge.com/advisory/HTB23121 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2012-1992 – CMS Made Simple 1.10.3 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2012-1992
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template). Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en admin/edituser.php en CMS Made Simple v1.10.3 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro de correo electrónico (también conocido como el campo Dirección de correo electrónico del usuario en la plantilla de edición). CMS Made Simple versions 1.10.3 and below suffer from a cross site scripting vulnerability. • http://www.securityfocus.com/bid/52850 http://www.webapp-security.com/wp-content/uploads/2012/04/CMS-Made-Simple-1.10.3-XSS-Vulnerability2.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2011-3718
https://notcve.org/view.php?id=CVE-2011-3718
CMS Made Simple (CMSMS) 1.9.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/TinyMCE/TinyMCE.module.php and certain other files. NOTE: this might overlap CVE-2007-5444. CMS Made Simple (CMSMS) v1.9.2 permite a atacantes remotos obtener información sensible a través de una petición directa a un archivo .php, lo que revela la ruta de instalación en un mensaje de error, como se demostró con modules/TinyMCE/TinyMCE.module.php y algunos otros archivos. NOTA: esto puede superponerse a CVE-2007-5444 • http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/%21_README http://code.google.com/p/inspathx/source/browse/trunk/paths_vuln/cmsmadesimple-1.9.2 http://www.openwall.com/lists/oss-security/2011/06/27/6 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2010-4663
https://notcve.org/view.php?id=CVE-2010-4663
Unspecified vulnerability in the News module in CMS Made Simple (CMSMS) before 1.9.1 has unknown impact and attack vectors. Vulnerabilidad no especificada en el módulo News en CMS Made Simple (CMSMS) anterior a v1.9.1 tiene un impacto desconocido y vectores de ataque. • http://forum.cmsmadesimple.org/viewtopic.php?t=49245 http://openwall.com/lists/oss-security/2011/03/29/2 http://openwall.com/lists/oss-security/2011/03/30/9 •
CVE-2010-2797
https://notcve.org/view.php?id=CVE-2010-2797
Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642. Una vulnerabilidad de salto de directorio en lib/translation.functions.php en CMS Made Simple antes de la versión v1.8.1 permite a atacantes remotos incluir y ejecutar archivos locales a través de un .. (Punto punto) en el parámetro default_cms_lang a un script de administración, tal y como se demuestra en admin/addbookmark.php. Se trata de una vulnerabilidad diferente a CVE-2008-5.642. • http://cross-site-scripting.blogspot.com/2010/07/cms-made-simple-18-local-file-inclusion.html http://secunia.com/advisories/40031 http://www.cmsmadesimple.org/2010/07/3/announcing-cms-made-simple-1-8-1-mankara http://www.openwall.com/lists/oss-security/2010/08/01/2 http://www.openwall.com/lists/oss-security/2010/08/02/8 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •